版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
●
MamGa
EquityResearch
Technology,Media,CommunicationsJuly7,2025
JonathanHo/p>
Thisreportisintendedforenelson@.Unauthorizeddistributionprohibited.
JasonAder,CFA+16172357519ArjunBhatia,CPAakeRoberge/p>
OntheGroundandIntheCloudADeveloperTechnologyQuarterly:
DevSecOpsRefreshEdition
SebastienNaji+12122456508GarrettBurkam/p>
Pleaserefertoimportantdisclosuresonpages41-42.Analystcertificationisonpage41.
WilliamBlairoranaffiliatedoesandseekstodobusinesswithcompaniescoveredinitsresearch
reports.Asaresult,investorsshouldbeawarethatthefirmmayhaveaconflictofinterestthatcouldaffecttheobjectivityofthisreport.Thisreportisnotintendedtoprovidepersonalinvestmentadvice.Theopinionsandrecommendationshereindonottakeintoaccountindividualclientcircumstances,objectives,orneedsandarenotintendedasrecommendationsofparticularsecurities,financial
instruments,orstrategiestoparticularclients.Therecipientofthisreportmustmakeitsownindependentdecisionsregardinganysecuritiesorfinancialinstrumentsmentionedherein.
WilliamBlair
JonathanHo+131236482762
Contents
Introduction 2
ExecutiveSummary 3
KeyTakeaways 4
ExaminingtheDevSecOpsMarketLandscape 7
AI’sImpactonDevSecOps 14
DevSecOpsMarketSizeandGrowthOutlook 16
DevSecOpsTrends 18
CoreValuePropositionsofDevSecOpsPlatforms 22
ProprietarySurveyofDevelopers 25
Appendix–PrivateCompanyProfiles 32
Glossary 38
Introduction
OntheGroundandIntheCloudisaquarterlypublicationproducedbytheWilliamBlairtechnologyteamthatdelvesintotrendsimpactingdevelopertechnologiesacrossawidescopeoftopicsthatincludessoftware
development,DevOps,database,analytics,andobservability.Overthepastdecade,developershavebecome
increasinglyimportantinfluencersacrossallorganizations,assoftwareapplicationsanddigitaltransformation
havebecomecriticaltobusinessoperations,customerinteraction,andcompetitiveadvantage.Morerecently,thistrendhasbeenaccentuatedbyblackswaneventsliketheCOVID-19pandemicandaslewofsoftwaresupply
chainattacks.Developersrepresenttheearlyadopterswhowilldeterminethesuccessofaparticularsoftwareproductorproject.Asaresult,webelieveitisessentialtoexaminethekeytechnologicalandculturaldynamicsimpactingthisall-importantcohortofworkers.
InthisDevSecOpsRefresheditionofOntheGroundandIntheCloud,weprovideupdatedresultsfromourmostrecentproprietarysurveyofdevelopers/practitioners,examinetheoverallDevSecOpsmarketanditsmajor
playersandhowithaschangedoverthelastyear,anddiscussthelatesttrendsinthespace.WealsoprovideourthoughtsonwhatimpactAImighthaveonDevSecOps,andwehighlightrelevantprivatecompanies.
WilliamBlair
JonathanHo+131236482763
ExecutiveSummary
DevSecOpsisthepracticeofembeddingsecuritythroughoutthesoftwaredevelopmentlifecycle(SDLC)toensurethatsecuritytesting,policies,andcontrolsareintegrateddirectlyintodeveloperandDevOpsworkflows.Insteadoftreatingsecurityasa
separatephaseattheendofthedevelopmentprocess,DevSecOpsmakesitacontinuousandsharedresponsibilityacrossIToperations,development,andsecurityteams.Thisapproachalignswithagileandcloud-nativesoftwaredeliverymethods,
whichenablesfasterandsafersoftwarereleasesbycatchingissuesearlierintheprocessandfosteringgreatercollaborationbetweentraditionallysiloedteams.ApplicationsandAPIsalsorepresentamajorattackvector,with25%ofalldatabreachestargetingapplicationlayervulnerabilities,accordingtoVerizon’slatestDataBreachInvestigationsReport.Softwaresupplychainsecurityisalsogainingmoreattentionafterhigh-profilebreaches,liketheSolarWindsandEquifaxattacks,highlightedtheneedtosecureallelementsinvolvedincreatinganddeliveringsoftware,especiallyopen-sourcesoftwaregiventhatit
accountsforupto90%ofmodernapplications.Thesetypesofattacksareshowingnosignsofslowing,withCheckPoint
recentlydiscoveringathreatactorknownasStargazerGoblinthathadcreatedanetworkofover3,000GitHubaccountstodistributemalwareandmaliciouslinksaspartofadistribution-as-a-service(DaaS)operation.
PleaseseeourprimerpieceonDevSecOpshere:
OntheGroundandIntheCloud:DevSecOpsEdition.
WebelieveDevSecOpsisessentialbecausetraditionalsecuritypracticesaresiloedandtooslowandreactivefortoday’srapidsoftwaredeliverycycles.DevSecOpsplatformsolutionshelporganizationsdetectandremediatevulnerabilitiesearlyinthe
developmentprocessbyintegratingsecurityintotheentireSDLC.Thesesolutionsprovideorganizationswiththeabilitytoscalesecurityacrossmultipleteamsandpipelines;enhancevisibilityintoapplicationsecurityandcomplianceposture;
improvecollaborationbetweendevelopers,security,andIToperationsteams;supportsecurityformodernapplicationarchitectures;betterintegrateDevSecOpstooling;andembedsecuritythroughoutthesoftwaredevelopmentprocess.
DevSecOpssolutionsalsoreducethecostofremediatingvulnerabilitieswhileenhancingdeveloperproductivitytoultimatelyenableorganizationstoshipsecurecodefasterwithfewerdisruptionsandlowerlong-termsecurityandcompliancecosts.
Fromourconversationswithprivatecompanies,publiccompanies,andindustryexpertsinthespace,webelievethe
DevSecOpscompetitivelandscapehasfourmajortypesofplayers:1)legacyapplicationsecurityvendors(likeCisco,Broadcom,IBM,andMicroFocus/OpenText);2)modernapplicationsecurityvendors(likeSnykandContrastSecurity);3)developer
platformproviders(likeGitHubandGitLab);and4)cloud-nativeapplicationprotectionplatform(CNAPP)vendors(likeWiz,
Sysdig,PaloAltoNetworks,andCrowdStrike).Inourview,developerplatforms,modernapplicationsecurityvendors,and
CNAPPvendorshavetherighttowininthemarketoverthemediumterm.Developerplatformsbenefitfromunmatched
integrationintodeveloperworkflows,broaddeveloperadoption,andsignificantplatformeffects,makingthesesolutionseasychoicesfordevelopersalreadyusingtheplatformtoshipsoftware.However,securityisnottheseplatforms’corecompetency,sowebelieveCNAPPsandmodernapplicationsecurityvendorsalsohavetherighttowin.Modernapplicationsecurityand
DevSecOpsvendorsarefocusedondevelopersecuritywithdeepexpertiseinthisdomain,whileCNAPPsofferunifiedcloudandapplicationsecuritysolutionsthatsecuresoftwareallthewayfromcodetoruntime.Longerterm,webelievemodern
DevSecOpscapabilitiesarelikelytofacecompetitivepressurefrombroaderplatformsthatincreasinglyoffersimilar
functionalityandwillbeconsolidatedintodeveloperplatformsandCNAPPs.Inourview,developerplatformsandCNAPPs
havethevaluepropositionsofreducingtoolsprawl,unifyingsecurityanddevelopmentworkflows,andmakingsecurityamoreintrinsicpartofthesoftwaredevelopmentlifecyclewithimprovedcapabilitiesovertime.WealsobelievethathyperscalersarelikelytocompetemoreseriouslyintheDevSecOpsspace,astheyownthecloudinfrastructurewheremodernapplicationsarebeingbuiltandrunandcanintegratesecuritycapabilities,whichcouldaccelerategivenGoogle’srecentacquisitionofWiz.
KeytrendsshapingDevSecOpsincludetheriseofplatformengineering,AIandautomation,softwaresupplychainsecurity,
applicationsecurityposturemanagement(ASPM),applicationdetectionandresponse(ADR),growingbutchallenging
adoption,andthepreferenceforplatformsolutions.WebelieveartificialintelligenceisreshapingDevSecOpsbyautomating
vulnerabilitydetection,eventtriage,incidentreports,sessionsummaries,andremediationwhilealsointroducingnewrisks
andchallengeswithAI-generatedcode.WeviewAIasadouble-edgedsword,asitbringssignificantadvantagesintermsof
developerproductivityandcybersecurityefficacy,butalsonewchallengesandsecurityrisks.Forexample,Metaconducteda
studyonAIcodegenerationandfoundthatthebetteranLLMisatwritingcode,theworseitisatavoidingvulnerablecoding
practices.Weexpectthistoimproveovertime,butitillustratestheheightenedriskAIbringsinthenearterm.Longerterm,webelieveAIagentswillfurtherdrivetheneedforDevSecOpstoolsasthesoftwaredeveloperroleshiftstothedevelopmentofAIagentsthatwillneedtobesecurebydesign.Overall,webelievetheDevSecOpsmarketissettobenefitfromAIasaresultoftheadvantagesofAI-enhancedcybersecurity,developersusingittowritemorecode,DevSecOpstoolsbecomingmoreefficientanduser-friendly,andtheneedtosecureAIitself,allofwhichweexpecttocontributetohigherdemandandadoptionrates.
WilliamBlair
JonathanHo+131236482764
KeyTakeaways
1.ModernDevSecOpsvendorsaregainingmarketshareduetogreaterdeveloperadoption,
integrations,performance,newtechnologycoverage,andusability.Webelievelegacyapplication
securityvendorshavemajorlimitationswithintegratingintoCI/CDpipelines,poordeliveryperformance,
andlaggedcoverageforemergingthreatvectors.Traditionaltoolsalsotypicallyfunctionasstandalone
productsusedsolelybysecurityteams,leadingtoaninefficientback-and-forthworkflowwithdevelopers
thatslowssoftwaredevelopmentandleadstosecurityissuesbeingidentifiedlateintheprocess.Modern
vendors,ontheotherhand,solveforthesechallengesandhaveamajoradvantagewithgreaterdeveloper
adoptiongiventhattheyaredesignedtobeusedbydevelopers.Theshifttocloudhasalsobenefitedmodernvendors,aslegacytoolswereoriginallybuiltforon-premisesenvironmentsandhavebeenslowtosupportnewercloudtechnologies.
2.DevSecOpsmarketremainshighlyfragmentedandrelativelyimmature.IDCforecaststheoverall
DevSecOpssoftwaretoolsmarkettogrowto$15.6billionin2028,representingafive-yearCAGRof21.6%(from2023through2028),drivenbytheneedtoshipapplicationssecurelyandquickly.Thetopfivemarketshareleaders(Synopsys,Microsoft,Veracode,PaloAltoNetworks,andCheckmarx)representjust26.5%oftheoverallmarket,suggestingthatthemarketisstilldynamicandmaturing.
3.Intheintermediateterm,webelievedeveloperplatforms,CNAPPs,andmodernapplicationsecurityvendorshavetherighttowinintheDevSecOpsmarket.Developer-centricplatformsbenefitfrom
unparalleledintegrationintodeveloperworkflows,broadadoption,andsignificantplatformeffects.Security,however,isnotthesevendors’corecompetency,sowebelieveCNAPPvendorsandmodernapplication
securityvendorsalsohavearighttowin.CNAPPplayersenableunifiedcloudandapplicationsecuritywith
comprehensivesolutionsthathelpbridgesoftwaredevelopmentandruntimeenvironments.Webelieve
modernDevSecOpsvendors,likeSnyk,arewellpositionedoverthemediumtermduetotheirdeveloper-firstapproachandeaseofuse,allowingdeveloperstoproactivelyaddresssecurityissuesdirectlyincode.Modernvendorshavebeenexpandingtheircapabilities,thoughtheyfacecompetitivepressuresfrombroader
platformsthatincreasinglyoffersimilarfunctionality.Inourview,however,modernDevSecOpsvendors’specializationindevelopersecurityputsthemaheadofthecompetitionandprovidestheopportunitytopotentiallypartnerwithCNAPPvendorsorcontinueexpandingcapabilities.
4.Longerterm,DevSecOpscapabilitieswilllikelyconsolidateintobroaderplatformsofferedby
developerplatformprovidersandCNAPPvendors.Inourview,organizationshaveastrongdesirefor
simplicity,reducedtoolsprawl,andunifiedsecurityanddevelopmentworkflows,andassecuritybecomesamoreintrinsicpartofthesoftwaredevelopmentlifecycleovertime,platformsprovidingend-to-endsoftwaredevelopmentandcloudmanagementcapabilitieshaveverystrongvaluepropositions.Webelievedeveloperplatforms,likeGitHubandGitLab,andCNAPPvendors,likeWiz,PaloAltoNetworks,andCrowdStrike,will
ultimatelyconsolidateDevSecOpsfeaturesintoabroaderplatformsolution.Hyperscalers(Amazon,
Microsoft,andGoogle)alsohaveanopportunitytoconsolidateDevSecOpsfeatureslongerterm,astheyownthecloudinfrastructureandcanintegratesecuritycapabilities,whichcouldaccelerategivenGoogle’srecentacquisitionofWiz,inourview.
5.Lookingahead,webelievetheDevSecOpsmarketwillmovetowardmoreunification,intelligence,andalignmentwithbusinessneedsthroughaconsolidatedsetofplatformscoveringapplication
securityacrossthefullspectrumofcodetoruntime.WebelievetheseplatformswillleverageAIand
automationforspeedandaccuracy,emphasizesoftwaresupplychainintegrity,andbeembeddedinto
developerworkflowstominimizeasmuchfrictionaspossible.Weexpectmajorcompetitorsindifferent
areas(likethehyperscalers,developerplatforms,specializedDevSecOpsvendors,andCNAPPs)toplay
distinctrolesbasedofftheircorecompetencies,andthatcustomerswilllikelygrowtheirDevSecOps
programswithoneofthesetypesofvendorsdependingontheirtypeoforganizationanditsmaturitylevel.
JonathanHo+131236482765
6.PurchasesofDevSecOpstoolsarestillultimatelymadebysecurityteams,assecuritybudgetslargelywinoutoverdevelopers.Developersandsecurityteamsusedtohaverelativelycomparableinfluenceon
decisionmaking.However,asbreacheshavetakenplaceandsecurityhasbecomeahigherpriority,developerinfluenceappearstobewaningrelativetothebudgetandauthoritywieldedbysecurityteams.Basedonourdiscussions,itappearsthatCISOs,applicationsecurityteams,andDevSecOpsteamstypicallycontrolthe
budgetformakingpurchasingdecisionsforDevSecOpstools,whiledevelopersdonotcurrentlyhavemuchinfluencedespitethemalsousingtheseproducts.Thus,vendorsneedtoprovideatoolthatisdeveloper
friendlywhilecommunicatingitsvaluetoasecurityperson,whichwebelievehasbeenachallengeinthe
industryandaninhibitortoadoptionbecausedeveloperssimplywillnotusethetoolifitistoocumbersomefortheirworkflow.
7.DevSecOpstoolcapabilitiesareincreasinglyoverlappingwithbroaderplatformsasvendorscontinuetoexpandtheircapabilities.WebelieveenterprisesareseekingholisticsolutionsthatseamlesslyintegratewithCI/CDpipelinestohaveallnecessarysecurityfunctionsinoneplace,whichwilllikelycontributeto
furtherconsolidationgoingforward.WebelievethedistinctionbetweenDevSecOpsandcloudsecuritytoolswillcontinuetofadeovertimeastheybecomepartofonetoolchainthatdeliverscontinuoussecurityfrom
codetocloud.DevSecOpssubmarkets,softwaresupplychainsecurity,andAPIsecurityarealsoblending
togetherandfurtherblurringtheboundariesofDevSecOps.Inourview,thethreeareasexperiencing
consolidationinDevSecOpsareapplicationsecuritytestingvendors,developerplatformproviders,and
CNAPPvendors.Wealsoexpectvendorconsolidationthroughacquisitionstoaccelerate,as2024hadrecord-highM&Aactivityinthesoftwaredevelopmentanddeploymentspace.
8.Overall,theDevSecOpsmarketissettobenefitfromAI,butitalsorepresentsoneofthebiggest
securitychallengestoday.WeexpectAItodrivehigherdemandandadoptionratesinDevSecOpsasaresultoftheadvantagesofAI-enhancedcybersecuritycapabilities,AIcodingassistantsbeingleveragedtowrite
morecodethatneedstobesecured,DevSecOpstoolsbecomingmoreefficientanduser-friendly,andtheneedtosecureAIitself.Longerterm,webelieveAIagentswillfurtherdrivetheneedforDevSecOpsassoftware
developmentbeginstofocusondevelopingAIagentsthatwillneedtobesecurebydesignlikeanapplication.WeviewquestionsoverhowtosafelyuseAIassomeofthemostimportantcybersecurityquestionsthatwillneedtobeansweredbeforeenterpriseadoptionaccelerates.
9.AutomationanddeveloperexperiencearecriticalcomponentsofDevSecOpstools.Webelieve
DevSecOpsrevolvesaroundautomation,asithelpsremovethefrictionbetweenDevOpsandsecurityteamsandenablesfasterandsaferdevelopmentcycles.Wealsobelieveautomationwillbeatthecenterofnext-
generationtools,especiallyasAIadoptionaccelerates,forbettersecuritytesting,fastervulnerability
detection,andautomaticremediationofcodeissues.Automationisalsoimportantforimprovingthe
developerexperienceastonotimpedeandslowdowntheirworkflows.Mostdeveloperswanttofocusonwritingcode,andautomationreducesthecognitiveloadfordevelopers,withautomatedsecuritymeasuresintegrateddirectlyintotheirworkflows,makingiteasierfordeveloperstoresolveissuesastheyariseandhelpingwithDevSecOpsadoption.
10.DevSecOpsadoptionismixedamongorganizationsandmaturitylevelsvarygreatly,evenwithin
organizations.Webelievethereisfurtherroomforadoptionaslessthanhalf(47%)oforganizations
regularlyemployDevSecOpspractices,accordingtoasurveybyTechstrongResearch.Manyorganizations
havebeenslowtoadoptDevSecOpspracticesandtechnologiesbecauseapplicationsecurityisdifficultand
constantlyevolvingwithnewtechnologies(likeAI)andsoftwaresupplychainconcerns,DevSecOpsrequiresalotoftoolsandresourcesthatmaybenewattackvectors,collaborationbetweendifferentteamscanbe
complex,anddeveloperexperienceremainsachallenge.WebelieveeveryDevOpsprogramtodayshouldbeaDevSecOpsprogramgiventhefastpaceofmodernsoftwaredevelopment,thefactthatcybersecurityrisknowrepresentsoverallbusinessrisk,andthatattacksonapplicationsandAPIscontinuetoincrease.
JonathanHo+131236482766
11.Despitechallenges,DevSecOpsadoptioncontinuestogrowasorganizationsrecognizetheimportanceofdeliveringsecuresoftwareandthelong-termbenefitsofreducedvulnerabilities,fasterincident
responsetimes,andimprovedcompliance.WebelieveorganizationswillcontinuetoadoptandmatureDevSecOpspracticesasplatformengineeringbecomesmorepopular,softwaresupplychainsneedgreatersecurity,AIdrivesmorecodeandvulnerabilities,developersbecomemorefamiliarwithsecuritytoolsandawareofsecurecodingpractices,andorganizationsrecognizetheneedfortheirsoftwaretobesecurebydesign.
12.DevSecOpsisbecomingsynonymouswithsoftwaresupplychainsecurity.DevSecOpstoolsare
increasinglyfocusingonsecuringthesoftwaresupplychain,withagreateremphasisonmanagingopen-
sourcecomponents,applicationbuildintegrity,andSBOMgenerationassoftwaresupplychainexploits
remainontherise.Webelieveopen-sourcesoftwareriskistopofmindfororganizationsasupto90%ofamodernapplicationiscomposedofopen-sourcecomponents.Effectivesoftwaresupplychainsecurity
involvesmanagingtheseopen-sourceandthird-partyelements,securecodingpractices,andCI/CDsecurity,allofwhichoverlapwithDevSecOpspractices.
13.DevSecOpsplatformsembedsecurityintosoftwaredevelopmentworkflowstodeliversecure
softwarewithoutsacrificingtherapidpaceofmoderndevelopmentpractices.DevSecOpsplatform
solutionshelporganizationsdetectandremediatevulnerabilitiesearlyinthedevelopmentprocessby
integratingsecurityintotheentiresoftwaredevelopmentlifecycle.Thesesolutionsprovideorganizations
withtheabilitytoscalesecurityacrossmultipleteamsandpipelines;enhancevisibilityintoapplication
securityandcomplianceposture;improvecollaborationbetweendevelopers,security,andIToperations
teams;supportsecurityformodernapplicationarchitectures;betterintegrateDevSecOpstooling;andembedsecuritythroughoutthesoftwaredevelopmentprocess.
JonathanHo+131236482767
ExaminingtheDevSecOpsMarketLandscape
InIDC’sWorldwideDevSecOpsSoftwareToolsMarketSharessnapshotfor2023,itestimatedthemarketsizeto
be$5.9billionwithgrowthof23.3%fromtheprioryear.ThetopfiveleadingvendorsinthemarketareSynopsys,witha6.6%marketshare;Microsoft,witha5.6%share;Veracode,witha5.4%share;PaloAltoNetworks,witha5.3%share;andCheckmarx,witha3.5%share.Together,thesefivevendorsrepresentjust26.5%oftheoverall
market,whichwebelieveindicatesthatthemarketisstillevolvingandrelativelyimmature.AccordingtoIDC,inmanymaturesoftwaremarkets,thetopfivevendorsrepresentmorethantwo-thirdsofthetotalrevenue.
Exhibit1
OntheGroundandIntheCloud;ADeveloperTechnologyQuarterly
DevSecOpsMarketShares,2023($inMillions)
2021
2022
2023
2023Share
(%)
2022-2023Growth
(%)
Synopsys
$314
$344
$388
6.6%
12.9%
Microsoft
$181
$257
$332
5.6%
28.9%
Veracode
$225
$272
$318
5.4%
16.8%
PaloAltoNetworks
$146
$222
$312
5.3%
40.9%
Checkmarx
$151
$172
$209
3.5%
21.9%
Snyk
$62
$143
$208
3.5%
45.0%
OpenText
$192
$192
$193
3.3%
0.2%
IBM
$150
$158
$166
2.8%
4.8%
Akamai
$121
$138
$157
2.7%
14.2%
GitLab
$49
$96
$156
2.7%
62.3%
TrendMicro
$110
$128
$142
2.4%
11.4%
$67
$101
$122
2.1%
20.5%
AmazonWebServices
$74
$94
$107
1.8%
13.7%
Lacework
$58
$81
$100
1.7%
23.1%
F5
$59
$70
$87
1.5%
24.3%
Cisco
$70
$73
$76
1.3%
4.7%
Perforce
$56
$63
$73
1.2%
15.6%
Mend
$41
$55
$64
1.1%
15.7%
SaltSecurity
$19
$34
$62
1.1%
83.1%
CyberArk
$41
$48
$62
1.0%
27.7%
ContrastSecurity
$42
$52
$60
1.0%
16.0%
AquaSecurity
$26
$35
$56
1.0%
62.3%
Other
$1,614
$1,949
$2,441
41.4%
25.3%
Total
$3,867
$4,775
$5,889
100.0%
23.3%
Source:WilliamBlairEquityResearchbasedonIDCestimates;IDCDevSecOpsSoftwareToolsMarketShares,August2024
JonathanHo+131236482768
Exhibit2
OntheGroundandIntheCloud;ADeveloperTechnologyQuarterly
DevSecOpsMarketSharesbyFunctionality,2023
InformationandDataSecurity3.9%
NetworkSecurity
19.7%
SecurityAnalytics
55.3%
$5.9BMarket
23.3%GrowthYoY
CNAPP
21.1%
Source:WilliamBlairEquityResearchbasedonIDCestimates;IDCDevSecOpsSoftwareToolsMarketShares,August2024
WebelievetherearefourmaingroupsofcompetitorsintheDevSecOpsmarket:1)legacyapplicationsecurity
vendors,2)modernapplicationsecurityvendors,3)CNAPPplayers,and4)developerplatformproviders.Over
thelongterm,webelievedeveloperplatforms(GitHubandGitLab)andCNAPPvendors(Wiz,PaloAltoNetworks,andCrowdStrike)havethestrongestrighttowinmarketshare.Developerplatformsbenefitfromunmatched
workflowintegration,developerfamiliarity,andplatformeffectsofdevelopersnaturallyadoptingbuilt-in
securitycapabilitiesastheystreamlineandconsolidatetools.CNAPPvendorsofferunifiedcloudandapplicationsecuritywithbroadcapabilities(securityfromcodetoruntime)anddeepcloud-nativesecurityexpertise.Inthemediumterm,webelievemodernapplicationsecurityvendors(suchasSnykandContrastSecurity)haveaplaceinthemarket,astheyarehighlyinnovativeanddeveloper-centricbutfacepressurefromplatformsthatare
increasinglyembeddingsecurityfunctionality.Inourview,thesevendorswillhaveaplaceinthemarketaslongasthedeveloperplatformsandCNAPPvendorslagintheirdevelopersecuritycapabilities.Theycouldalso
partnerwithCNAPPvendors,thoughlongerterm,weseepotentialforthesebroadervendorstomoreeffectivelycompeteorpossiblyacquiresomepureapplicationsecurityvendorstoensuretheyhaveastrongsetof
capabilities.Webelievelegacyvendorsarecurrentlylosingmarketshareandarecontinuallyhavingtoadapttomodernworkflows.Overall,webelievethevaluepropositionsofdeveloperplatformsandCNAPPvendorsare
verystrongandthattheyholdastrategicadvantageintheDevSecOpslandscapebasedonintegratedworkflows,platformconsolidation,enterpriseadoption,andtheacceleratedshifttowardcloud-nativearchitectures.
LegacyApplicationSecurityVendors
LegacyvendorsintheDevSecOpsspacearethosethattypicallyoriginatedfromearlyapplicationsecuritytoolsbeforethecloud-nativeera.ThesevendorsincludecompanieslikeCisco,IBM,Broadcom,andMicroFocus
(OpenText)thatgenerallybuilttheirreputationsontraditionalstaticapplicationsecuritytesting(SAST)anddynamicapplicationsecuritytesting(DAST)toolsthatwereusuallydeliveredason-premisesenterprise
solutions.WebelievetheselegacytoolsarenotbuiltforthespeedthatDevSecOpsrequiresandareless
integratedintodeveloper
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026湖南郴州市第一人民医院招聘58人备考题库及答案详解【网校专用】
- 2025吉林省吉林大学材料科学与工程学院郎兴友教授团队博士后招聘1人备考题库及答案详解(典优)
- 2026广东警官学院招聘事业单位人员5人备考题库带答案详解(培优b卷)
- 2026广东汕头大学医学院第一批招聘6人备考题库附答案详解(典型题)
- 2026湖北长江产业资产经营管理有限公司所属企业招聘12人备考题库及答案详解【夺冠系列】
- 2026浙江师范大学行知学院招聘辅导员9人备考题库及1套参考答案详解
- 2026广东湛江市雷州供销助禾农业科技服务有限公司招聘5人备考题库附答案详解(精练)
- 2026广东广州市白云区嘉禾街道综合事务中心合同制聘员招聘7人备考题库带答案详解(研优卷)
- 2026江苏保险公司销售人员招聘备考题库带答案详解(培优a卷)
- 2026江苏保险公司销售人员招聘备考题库附参考答案详解(达标题)
- 2026年电网大面积停电应急演练方案
- 2026 年浙江大学招聘考试题库解析
- 2026上半年北京事业单位统考大兴区招聘137人备考题库(第一批)及参考答案详解【考试直接用】
- 2026年湖南省长沙市高二下学期第一次月考化学模拟试卷02(人教版)(试卷及参考答案)
- 成都交易集团有限公司2026年第一批社会集中公开招聘笔试备考题库及答案解析
- 2026年山西经贸职业学院单招综合素质考试题库附答案详解(综合题)
- GB/T 14983-2008耐火材料抗碱性试验方法
- GA 576-2018防尾随联动互锁安全门通用技术条件
- 2023年同等学力申硕法语真题答案
- 卓越教育学管师工作标准手册
- 中国石油大学(华东)PPT模板
评论
0/150
提交评论